SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Wispr AI is building the voice interface for computing, with products like Flow (natural voice interaction in any application) and Notetaker (context-building across conversations). The company is focused on creating AI systems that can perceive, understand, and take action with earned trust.
You will own the customer assurance and compliance programs as Security Assurance & GRC Lead, reporting to the vCISO. This is a strategic, customer-facing role that combines program leadership with hands-on execution.
Key responsibilities:
- Own the GRC roadmap across SOC 2 Type II, ISO 27001, privacy, and enterprise customer requirements, prioritizing enterprise blockers by business impact.
- Lead customer assurance end-to-end: represent Wispr on security calls and reviews, own questionnaires, due-diligence requests, vendor assessments, and RFP security sections. Drive cross-functional resolution on escalations.
- Engage early on strategic deals to anticipate objections and build security plans with Sales.
- Improve the Trust Center, standard responses, and security narratives to enable customer self-service and demonstrate posture clearly.
- Build systems and processes: track turnaround times, identify recurring objections and repetitive work, then standardize and automate using tools like Drata, SafeBase, and Linear.
- Partner with the compliance engineer to strengthen process design, prioritization, and follow-through.
- Feed patterns from security reviews into Product and Engineering roadmaps (SSO/SCIM, audit logs, permissions, retention, data residency, AI/data handling).
- Own the AI security narrative: answer customer questions about model providers, training and data usage, retention, subprocessors, and data flows. Coordinate clear customer communication during incidents.
- Keep compliance running: coordinate audit evidence, track deadlines, maintain controls and policies, drive remediation, and keep the risk register, vendor inventory, and compliance calendar current.
You'll work closely with Engineering, Product, Legal, Sales, Customer Success, and Support. Much of the role is customer-facing; you'll lead security conversations with sophisticated buyers, represent posture accurately (including being direct about gaps), and know when to escalate.
Success in the first six months means: owning the customer assurance motion end-to-end, establishing a clear GRC roadmap with leadership sign-off, materially reducing security-review turnaround time through standardization and automation, and giving leadership a current view of major security risks and enterprise blockers with clear ownership and plans.
REQUIREMENTS:
- Depth in GRC, security compliance, customer assurance, IT audit, or risk management, with range to own both program and customer conversation.
- Experience leading customer security reviews and explaining security to technical and non-technical audiences.
- Working knowledge of SOC 2, ISO 27001, or similar frameworks, and ability to turn them into practical roadmaps.
- Sound judgment on what constitutes a material enterprise blocker versus what can wait, and what you can answer versus what needs escalation.
- Track record of creating structure around manual or ambiguous work and improving underlying systems.
- Strong written and verbal communication on risk, posture, and technical constraints, plus project-management discipline to drive cross-functional work to completion.
- Comfort working across Engineering, Product, IT, Legal, Sales, Customer Success, and Support; willingness to do operational work while reducing it over time.
NICE TO HAVE:
- Startup or growth-stage SaaS experience supporting enterprise customers.
- Experience establishing or scaling a compliance or customer assurance program.
- Familiarity with Drata, Vanta, SafeBase, or similar tools, and standard questionnaires (SIG, CAIQ, HECVAT, VSAQ).
- Working knowledge of cloud security, access control, encryption, logging, vulnerability management, incident response, and SaaS architecture.
- Familiarity with AI security and privacy: model providers, training and data usage, retention, subprocessors, data flows, access boundaries.
- Exposure to GDPR, CCPA, HIPAA, data residency, or vendor-risk management.
- Experience building automations or integrations for compliance work.
- Security+, CISA, CGRC, ISO 27001 Lead Implementer, or similar certification.